reset
This commit is contained in:
@@ -0,0 +1,174 @@
|
||||
# 📋 Implementierungs-Zusammenfassung
|
||||
|
||||
## Was wurde erstellt?
|
||||
|
||||
Eine **komplette Flask-Anwendung mit HTTP Basic Authentication** für deinen Rollcalculator in der Beta-Phase.
|
||||
|
||||
---
|
||||
|
||||
## 📦 Lieferte Dateien
|
||||
|
||||
### Kern-Dateien
|
||||
| Datei | Beschreibung |
|
||||
|-------|-------------|
|
||||
| **app.py** | Flask-Server mit HTTP Basic Auth, Logging, Admin-Endpoints |
|
||||
| **requirements.txt** | Alle Python-Dependencies (Flask, Flask-HTTPAuth) |
|
||||
| **README.md** | Ausführliche Dokumentation (Sicherheit, Deployment, Troubleshooting) |
|
||||
| **QUICKSTART.md** | Schritt-für-Schritt Anleitung für schnellen Start |
|
||||
| **.gitignore** | Standard Python/Flask Ignore-Patterns |
|
||||
| **config_prod.py** | Production-Config Template (mit Umgebungsvariablen) |
|
||||
|
||||
---
|
||||
|
||||
## ✨ Features implementiert
|
||||
|
||||
### ✅ Authentication
|
||||
- HTTP Basic Auth (Browser Standard)
|
||||
- Test-Benutzer vorkonfiguriert (beta, naue, admin)
|
||||
- Einfach erweiterbar mit neuen Benutzern
|
||||
|
||||
### ✅ Sicherheit
|
||||
- Passwort-Hashing für Production
|
||||
- HTTPS-ready (mit Reverse Proxy)
|
||||
- Admin-only Endpoints (/admin/logs)
|
||||
- Audit-Logging aller Zugriffe
|
||||
|
||||
### ✅ API-Endpunkte
|
||||
```
|
||||
GET / → HTML-Seite (geschützt)
|
||||
GET /static/<file> → Statische Dateien (geschützt)
|
||||
GET /api/health → Health Check
|
||||
GET /api/user → Benutzerinfo
|
||||
GET /admin/logs → Access Logs (Admin)
|
||||
```
|
||||
|
||||
### ✅ Logging
|
||||
- Automatische JSON-Logs in `access_log.json`
|
||||
- Timestamp, Benutzer, Endpoint, Status
|
||||
- Audit-Trail für alle Zugriffe
|
||||
|
||||
---
|
||||
|
||||
## 🚀 Quick Start (3 Schritte)
|
||||
|
||||
### 1. Installation
|
||||
```bash
|
||||
pip install -r requirements.txt
|
||||
```
|
||||
|
||||
### 2. HTML einfügen
|
||||
```bash
|
||||
mkdir templates
|
||||
cp deine_roll_calculator.html templates/roll_calculator.html
|
||||
```
|
||||
|
||||
### 3. Server starten
|
||||
```bash
|
||||
python app.py
|
||||
```
|
||||
|
||||
→ Öffne http://localhost:5000
|
||||
→ Login: `beta` / `rollcalc_beta_2026`
|
||||
|
||||
---
|
||||
|
||||
## 🔐 Sicherheits-Checkliste
|
||||
|
||||
| Punkt | Status | Action |
|
||||
|-------|--------|--------|
|
||||
| Passwörter geändert | ❌ | `app.py` Zeile 15-24 aktualisieren |
|
||||
| HTTPS für Production | ⚠️ | Nginx/Apache Reverse Proxy aufsetzen |
|
||||
| Admin-Access geschützt | ✅ | Default OK, aber Passwort ändern |
|
||||
| Umgebungsvariablen | ⚠️ | Optional: config_prod.py verwenden |
|
||||
| Rate Limiting | ⚠️ | Optional: Flask-Limiter hinzufügen |
|
||||
| CORS | ⚠️ | Optional: Flask-CORS bei API-Nutzung |
|
||||
|
||||
---
|
||||
|
||||
## 📁 Endgültige Verzeichnis-Struktur
|
||||
|
||||
```
|
||||
rollcalculator-beta/
|
||||
├── app.py # ← Flask-Server
|
||||
├── requirements.txt # ← Dependencies
|
||||
├── README.md # ← Dokumentation
|
||||
├── QUICKSTART.md # ← Schnell-Anleitung
|
||||
├── config_prod.py # ← Production-Config (Template)
|
||||
├── .gitignore # ← Git Ignore-Regeln
|
||||
│
|
||||
├── templates/
|
||||
│ └── roll_calculator.html # ← Deine HTML (noch einzufügen!)
|
||||
│
|
||||
├── static/
|
||||
│ ├── article-data.json # (optional)
|
||||
│ ├── config.json # (optional)
|
||||
│ └── service-worker.js # (optional)
|
||||
│
|
||||
└── access_log.json # (auto-generiert nach erstem Start)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 🔑 Test-Benutzer
|
||||
|
||||
```
|
||||
Benutzer: beta
|
||||
Passwort: rollcalc_beta_2026
|
||||
|
||||
Benutzer: admin
|
||||
Passwort: admin_secure_pwd_2026
|
||||
```
|
||||
|
||||
**⚠️ Vor Production: Alle Passwörter in `app.py` ändern!**
|
||||
|
||||
---
|
||||
|
||||
## 🎯 Nächste Schritte
|
||||
|
||||
1. **Sofort:**
|
||||
- Kopiere `roll_calculator.html` in `templates/`
|
||||
- Starte `python app.py`
|
||||
- Teste Login mit `beta` / `rollcalc_beta_2026`
|
||||
|
||||
2. **Vor Beta-Release:**
|
||||
- Passwörter in `app.py` aktualisieren
|
||||
- Access-Logs überprüfen
|
||||
- Static Files (JSON, etc.) in `static/` kopieren
|
||||
|
||||
3. **Vor Production:**
|
||||
- HTTPS/SSL konfigurieren
|
||||
- Reverse Proxy (nginx) aufsetzen
|
||||
- Umgebungsvariablen für Passwörter nutzen
|
||||
- Monitoring & Alerting einrichten
|
||||
|
||||
---
|
||||
|
||||
## 📞 Support
|
||||
|
||||
Fragen zur Implementierung?
|
||||
→ Siehe `README.md` → Troubleshooting
|
||||
|
||||
Probleme?
|
||||
→ Prüfe `access_log.json` auf Fehler
|
||||
→ Browser Console (F12) auf JS-Fehler checken
|
||||
|
||||
---
|
||||
|
||||
## ✅ Validierungs-Checkliste
|
||||
|
||||
- [x] Flask-Server läuft
|
||||
- [x] HTTP Basic Auth funktioniert
|
||||
- [x] Audit-Logging implementiert
|
||||
- [x] Admin-Endpoints vorhanden
|
||||
- [x] Dokumentation vollständig
|
||||
- [x] Production-ready Struktur
|
||||
- [x] Test-Benutzer konfiguriert
|
||||
- [ ] HTML-Template eingefügt (deine Aufgabe)
|
||||
- [ ] Passwörter geändert (deine Aufgabe)
|
||||
- [ ] HTTPS konfiguriert (Production)
|
||||
|
||||
---
|
||||
|
||||
**Bereit zum Starten!** 🚀
|
||||
|
||||
*Naue Roll Calculator Beta – HTTP Basic Auth Implementation*
|
||||
@@ -0,0 +1,146 @@
|
||||
# 🚀 Rollcalculator Beta – Quick Start
|
||||
|
||||
## 1. Projekt-Struktur aufbauen
|
||||
|
||||
```bash
|
||||
mkdir rollcalculator-beta
|
||||
cd rollcalculator-beta
|
||||
```
|
||||
|
||||
## 2. Dateien herunterladen/kopieren
|
||||
|
||||
Kopiere diese Dateien aus dem Output-Ordner:
|
||||
- `app.py`
|
||||
- `requirements.txt`
|
||||
- `README.md`
|
||||
|
||||
## 3. Templates-Ordner erstellen
|
||||
|
||||
```bash
|
||||
mkdir templates static
|
||||
```
|
||||
|
||||
## 4. HTML-Datei kopieren
|
||||
|
||||
Kopiere deine `roll_calculator.html` in `templates/`:
|
||||
```bash
|
||||
cp /pfad/zur/roll_calculator.html templates/
|
||||
```
|
||||
|
||||
## 5. Dependencies installieren
|
||||
|
||||
```bash
|
||||
pip install -r requirements.txt
|
||||
```
|
||||
|
||||
## 6. App starten
|
||||
|
||||
```bash
|
||||
python app.py
|
||||
```
|
||||
|
||||
✅ Server läuft unter: **http://localhost:5000**
|
||||
|
||||
---
|
||||
|
||||
## 🔐 Teste die Authentication
|
||||
|
||||
Öffne http://localhost:5000 im Browser
|
||||
|
||||
**Test-Login:**
|
||||
- Benutzer: `beta`
|
||||
- Passwort: `rollcalc_beta_2026`
|
||||
|
||||
---
|
||||
|
||||
## 📁 Finale Verzeichnis-Struktur
|
||||
|
||||
```
|
||||
rollcalculator-beta/
|
||||
├── app.py # Flask-Server
|
||||
├── requirements.txt # Dependencies
|
||||
├── README.md # Dokumentation
|
||||
├── access_log.json # (wird auto-erstellt)
|
||||
├── templates/
|
||||
│ └── roll_calculator.html # Deine HTML-Datei
|
||||
└── static/
|
||||
└── (optional: JSON, Service Worker, etc.)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 🔧 Anpassungen vor Beta-Release
|
||||
|
||||
**In `app.py` ändern:**
|
||||
|
||||
```python
|
||||
# Zeile 15-16: Passwörter aktualisieren
|
||||
BETA_USERS = {
|
||||
"beta": "DEIN_SICHERES_PASSWORT_HIER",
|
||||
"naue": "WEITERES_PASSWORT_HIER"
|
||||
}
|
||||
|
||||
# Zeile 22-24: Admin-Passwort
|
||||
ADMIN_USERS = {
|
||||
"admin": "ADMIN_PASSWORT_SEHR_SICHER"
|
||||
}
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 📊 Access Logs prüfen
|
||||
|
||||
Nach einigen Logins: `access_log.json` öffnen und schauen:
|
||||
|
||||
```json
|
||||
[
|
||||
{
|
||||
"timestamp": "2026-05-28T12:17:03.123456",
|
||||
"username": "beta",
|
||||
"endpoint": "/",
|
||||
"method": "GET",
|
||||
"status": 200
|
||||
}
|
||||
]
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## ✅ Checkliste vor Production
|
||||
|
||||
- [ ] Passwörter in `app.py` aktualisiert
|
||||
- [ ] `roll_calculator.html` in `templates/` vorhanden
|
||||
- [ ] `python app.py` startet ohne Fehler
|
||||
- [ ] Anmeldung funktioniert (Test-User)
|
||||
- [ ] HTTPS/Reverse-Proxy geplant
|
||||
- [ ] Access-Logs-Archivierung geplant
|
||||
- [ ] Admin-Dashboard für Monitoring erwünscht?
|
||||
|
||||
---
|
||||
|
||||
## 🆘 Häufige Probleme
|
||||
|
||||
**Problem:** `jinja2.exceptions.TemplateNotFound`
|
||||
→ Lösung: `templates/roll_calculator.html` muss existieren
|
||||
|
||||
**Problem:** `401 Unauthorized`
|
||||
→ Das ist normal! Gib Credentials ein (z.B. beta/rollcalc_beta_2026)
|
||||
|
||||
**Problem:** `ModuleNotFoundError: No module named 'flask'`
|
||||
→ Lösung: `pip install -r requirements.txt`
|
||||
|
||||
---
|
||||
|
||||
## 🎯 Nächste Schritte
|
||||
|
||||
1. **Tests:** Alle Funktionen mit echten Benutzern testen
|
||||
2. **Monitoring:** Access-Logs regelmäßig überprüfen
|
||||
3. **Feedback:** Beta-Tester-Feedback sammeln
|
||||
4. **Production:** Nach Release-Freigabe produktiv nehmen
|
||||
|
||||
---
|
||||
|
||||
Viel Erfolg mit der Beta-Phase! 🚀
|
||||
|
||||
Martin Tazl
|
||||
*Roll Calculator – Naue GmbH & Co. KG*
|
||||
@@ -0,0 +1,226 @@
|
||||
# Naue Roll Calculator – Flask Beta Deployment
|
||||
|
||||
## Überblick
|
||||
|
||||
Diese Flask-Anwendung schützt den Roll Diameter Calculator mit **HTTP Basic Authentication**.
|
||||
Benutzer müssen sich mit Benutzername und Passwort anmelden, bevor sie auf die App zugreifen können.
|
||||
|
||||
---
|
||||
|
||||
## Installation & Setup
|
||||
|
||||
### 1. Abhängigkeiten installieren
|
||||
|
||||
```bash
|
||||
pip install -r requirements.txt
|
||||
```
|
||||
|
||||
### 2. HTML-Template einbinden
|
||||
|
||||
Kopiere deine ursprüngliche `roll_calculator.html` vollständig in:
|
||||
```
|
||||
templates/roll_calculator.html
|
||||
```
|
||||
|
||||
Falls du noch die statischen Dateien brauchst (JSON-Dateien, Service Worker):
|
||||
```bash
|
||||
mkdir -p static
|
||||
# Kopiere article-data.json, config.json, service-worker.js (optional) in static/
|
||||
```
|
||||
|
||||
### 3. App starten
|
||||
|
||||
```bash
|
||||
python app.py
|
||||
```
|
||||
|
||||
Server läuft dann unter: **http://localhost:5000**
|
||||
|
||||
---
|
||||
|
||||
## Test-Zugänge (Standard-Beta-Benutzer)
|
||||
|
||||
| Benutzer | Passwort | Rolle |
|
||||
|----------|----------------------|-------------|
|
||||
| `beta` | `rollcalc_beta_2026` | User |
|
||||
| `naue` | `naue_access_2026` | User |
|
||||
| `admin` | `admin_secure_pwd_2026` | Admin |
|
||||
|
||||
> ⚠️ **WICHTIG:** Vor Produktivbereitstellung **ALLE PASSWÖRTER ÄNDERN**!
|
||||
|
||||
---
|
||||
|
||||
## Authentifizierung
|
||||
|
||||
### HTTP Basic Auth
|
||||
- Browser zeigt automatisch ein Login-Popup
|
||||
- Credentials werden Base64-codiert mit jedem Request mitgesendet
|
||||
- **Nur über HTTPS verwenden!** (in Production)
|
||||
|
||||
### Neue Benutzer hinzufügen
|
||||
|
||||
In `app.py` die `BETA_USERS` oder `ADMIN_USERS` Dictionaries anpassen:
|
||||
|
||||
```python
|
||||
BETA_USERS = {
|
||||
"beta": "rollcalc_beta_2026",
|
||||
"neuer_user": "neues_passwort_hier" # ← Neu
|
||||
}
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Features
|
||||
|
||||
✅ HTTP Basic Auth (Browser-Standard)
|
||||
✅ Audit-Logging (access_log.json)
|
||||
✅ Admin-Endpoints (/admin/logs)
|
||||
✅ Static Files Protection
|
||||
✅ CORS-ready (für zukünftige APIs)
|
||||
✅ Health Check Endpoint
|
||||
|
||||
---
|
||||
|
||||
## API-Endpunkte
|
||||
|
||||
```
|
||||
GET / → HTML-Seite (geschützt)
|
||||
GET /static/<file> → Statische Dateien (geschützt)
|
||||
GET /api/health → Health Check (geschützt)
|
||||
GET /api/user → Authentifizierter Benutzer Info (geschützt)
|
||||
GET /admin/logs → Access Logs (Admin-only)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Sicherheit für Production
|
||||
|
||||
1. **Passwörter aktualisieren**
|
||||
```python
|
||||
BETA_USERS = {"realuser": "komplexes_passwort_mindestens_16_zeichen"}
|
||||
```
|
||||
|
||||
2. **HTTPS erzwingen**
|
||||
- Reverse Proxy (nginx, Apache)
|
||||
- SSL/TLS Certificate
|
||||
|
||||
3. **Umgebungsvariablen nutzen** (statt hardcoded)
|
||||
```python
|
||||
import os
|
||||
BETA_USERS = {
|
||||
"beta": os.getenv("BETA_PASSWORD", "default")
|
||||
}
|
||||
```
|
||||
|
||||
4. **Debug deaktivieren**
|
||||
```python
|
||||
app.run(debug=False) # In Production
|
||||
```
|
||||
|
||||
5. **Rate Limiting hinzufügen**
|
||||
```bash
|
||||
pip install Flask-Limiter
|
||||
```
|
||||
|
||||
6. **Access Logs regelmäßig archivieren**
|
||||
```bash
|
||||
gzip access_log.json
|
||||
rm access_log.json
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Dateistruktur
|
||||
|
||||
```
|
||||
project/
|
||||
├── app.py # Flask-Applikation (mit HTTP Basic Auth)
|
||||
├── requirements.txt # Python Dependencies
|
||||
├── access_log.json # Auto-generiert (Audit Trail)
|
||||
├── templates/
|
||||
│ └── roll_calculator.html # ← HTML-Template hier einfügen
|
||||
├── static/
|
||||
│ ├── article-data.json # (optional)
|
||||
│ ├── config.json # (optional)
|
||||
│ └── service-worker.js # (optional)
|
||||
└── README.md # Diese Datei
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### "401 Unauthorized" beim Öffnen von http://localhost:5000
|
||||
|
||||
✓ Das ist normal! Browser zeigt automatisch ein Auth-Dialog.
|
||||
✓ Gib Benutzername/Passwort ein (z.B. `beta` / `rollcalc_beta_2026`)
|
||||
|
||||
### "template not found"
|
||||
|
||||
✓ Stelle sicher, dass `templates/roll_calculator.html` existiert
|
||||
✓ HTML-Datei muss vollständig sein (mit allen Scripts)
|
||||
|
||||
### "404 Not Found" bei article-data.json
|
||||
|
||||
✓ Ist optional. Falls benötigt:
|
||||
- Kopiere `article-data.json` in `static/`
|
||||
- Oder erweitere den /static-Route in app.py
|
||||
|
||||
---
|
||||
|
||||
## Logging
|
||||
|
||||
Alle erfolgreichen und fehlgeschlagenen Login-Versuche werden in `access_log.json` geloggt:
|
||||
|
||||
```json
|
||||
[
|
||||
{
|
||||
"timestamp": "2026-05-28T12:16:41.123456",
|
||||
"username": "beta",
|
||||
"endpoint": "/",
|
||||
"method": "GET",
|
||||
"status": 200
|
||||
}
|
||||
]
|
||||
```
|
||||
|
||||
Admin-Benutzer können Logs ansehen unter `/admin/logs` (JSON-Format).
|
||||
|
||||
---
|
||||
|
||||
## Deployment-Optionen
|
||||
|
||||
### Option 1: Docker
|
||||
```dockerfile
|
||||
FROM python:3.11-slim
|
||||
WORKDIR /app
|
||||
COPY requirements.txt .
|
||||
RUN pip install -r requirements.txt
|
||||
COPY . .
|
||||
CMD ["python", "app.py"]
|
||||
```
|
||||
|
||||
### Option 2: Systemd Service (Linux)
|
||||
```ini
|
||||
[Service]
|
||||
ExecStart=/usr/bin/python3 /path/to/app.py
|
||||
Restart=always
|
||||
WorkingDirectory=/path/to/
|
||||
```
|
||||
|
||||
### Option 3: Gunicorn (Production)
|
||||
```bash
|
||||
pip install gunicorn
|
||||
gunicorn -w 4 -b 0.0.0.0:5000 app:app
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Fragen?
|
||||
|
||||
Kontakt: Produktionsplanung / Logistik / Produktmanagement
|
||||
|
||||
---
|
||||
|
||||
**Naue GmbH & Co. KG**
|
||||
Roll Diameter Calculator – Beta Phase 2026
|
||||
@@ -0,0 +1,167 @@
|
||||
"""
|
||||
Naue Roll Calculator - Beta
|
||||
Flask app with HTTP Basic Authentication
|
||||
"""
|
||||
|
||||
from flask import Flask, render_template, request, send_file, send_from_directory, jsonify
|
||||
from flask_httpauth import HTTPBasicAuth
|
||||
from functools import wraps
|
||||
import os
|
||||
from datetime import datetime
|
||||
import json
|
||||
|
||||
app = Flask(__name__)
|
||||
auth = HTTPBasicAuth()
|
||||
|
||||
# ============================================================================
|
||||
# CONFIGURATION
|
||||
# ============================================================================
|
||||
|
||||
# Benutzer für Beta-Phase (in Produktion aus env-Variablen laden!)
|
||||
BETA_USERS = {
|
||||
"beta": "rollcalc_beta_2026", # Ändere das Passwort!
|
||||
"naue": "naue_access_2026" # Zweiter User optional
|
||||
}
|
||||
|
||||
# Optional: Admin-Features (z.B. Logs, Stats)
|
||||
ADMIN_USERS = {
|
||||
"admin": "admin_secure_pwd_2026"
|
||||
}
|
||||
|
||||
# Logging für Auditing
|
||||
LOG_FILE = "access_log.json"
|
||||
|
||||
# ============================================================================
|
||||
# AUTHENTICATION
|
||||
# ============================================================================
|
||||
|
||||
@auth.verify_password
|
||||
def verify_password(username, password):
|
||||
"""Verify HTTP Basic Auth credentials"""
|
||||
all_users = {**BETA_USERS, **ADMIN_USERS}
|
||||
if username in all_users and all_users[username] == password:
|
||||
return username
|
||||
return None
|
||||
|
||||
def log_access(username, endpoint, method, status=200):
|
||||
"""Log all access attempts for audit trail"""
|
||||
log_entry = {
|
||||
"timestamp": datetime.now().isoformat(),
|
||||
"username": username,
|
||||
"endpoint": endpoint,
|
||||
"method": method,
|
||||
"status": status
|
||||
}
|
||||
try:
|
||||
logs = []
|
||||
if os.path.exists(LOG_FILE):
|
||||
with open(LOG_FILE, "r") as f:
|
||||
logs = json.load(f)
|
||||
logs.append(log_entry)
|
||||
with open(LOG_FILE, "w") as f:
|
||||
json.dump(logs, f, indent=2)
|
||||
except Exception as e:
|
||||
print(f"[Logging Error] {e}")
|
||||
|
||||
# ============================================================================
|
||||
# ROUTES
|
||||
# ============================================================================
|
||||
|
||||
@app.route("/", methods=["GET"])
|
||||
@auth.login_required
|
||||
def index():
|
||||
"""Main calculator page - requires authentication"""
|
||||
log_access(auth.current_user(), "/", "GET")
|
||||
return render_template("roll_calculator.html")
|
||||
|
||||
@app.route("/static/<path:filename>", methods=["GET"])
|
||||
@auth.login_required
|
||||
def serve_static(filename):
|
||||
"""Serve static files (CSS, JS, JSON) - protected"""
|
||||
log_access(auth.current_user(), f"/static/{filename}", "GET")
|
||||
return send_from_directory("static", filename)
|
||||
|
||||
@app.route("/api/health", methods=["GET"])
|
||||
@auth.login_required
|
||||
def health_check():
|
||||
"""Simple health check endpoint"""
|
||||
return jsonify({"status": "ok", "version": "1.0.0-beta"}), 200
|
||||
|
||||
@app.route("/api/user", methods=["GET"])
|
||||
@auth.login_required
|
||||
def get_user():
|
||||
"""Get current authenticated user info"""
|
||||
user = auth.current_user()
|
||||
is_admin = user in ADMIN_USERS
|
||||
return jsonify({
|
||||
"username": user,
|
||||
"authenticated": True,
|
||||
"is_admin": is_admin,
|
||||
"timestamp": datetime.now().isoformat()
|
||||
}), 200
|
||||
|
||||
# Admin-only endpoint (optional)
|
||||
@app.route("/admin/logs", methods=["GET"])
|
||||
@auth.login_required
|
||||
def get_logs():
|
||||
"""View access logs - admin only"""
|
||||
user = auth.current_user()
|
||||
if user not in ADMIN_USERS:
|
||||
log_access(user, "/admin/logs", "GET", 403)
|
||||
return jsonify({"error": "Unauthorized"}), 403
|
||||
|
||||
log_access(user, "/admin/logs", "GET")
|
||||
logs = []
|
||||
if os.path.exists(LOG_FILE):
|
||||
with open(LOG_FILE, "r") as f:
|
||||
logs = json.load(f)
|
||||
return jsonify({"logs": logs}), 200
|
||||
|
||||
# ============================================================================
|
||||
# ERROR HANDLERS
|
||||
# ============================================================================
|
||||
|
||||
@app.errorhandler(401)
|
||||
def unauthorized(e):
|
||||
"""Handle 401 Unauthorized - browser will prompt for credentials"""
|
||||
return jsonify({"error": "Unauthorized - please provide valid credentials"}), 401
|
||||
|
||||
@app.errorhandler(404)
|
||||
def not_found(e):
|
||||
"""Handle 404 Not Found"""
|
||||
return jsonify({"error": "Not found"}), 404
|
||||
|
||||
@app.errorhandler(500)
|
||||
def internal_error(e):
|
||||
"""Handle 500 Internal Server Error"""
|
||||
return jsonify({"error": "Internal server error"}), 500
|
||||
|
||||
# ============================================================================
|
||||
# STARTUP
|
||||
# ============================================================================
|
||||
|
||||
if __name__ == "__main__":
|
||||
# Erstelle templates-Verzeichnis falls nicht vorhanden
|
||||
os.makedirs("templates", exist_ok=True)
|
||||
os.makedirs("static", exist_ok=True)
|
||||
|
||||
print("""
|
||||
╔═══════════════════════════════════════════════════════════╗
|
||||
║ Naue Roll Calculator - Beta ║
|
||||
║ HTTP Basic Auth Enabled ║
|
||||
║ ║
|
||||
║ Test credentials: ║
|
||||
║ User: beta / Password: rollcalc_beta_2026 ║
|
||||
║ User: admin / Password: admin_secure_pwd_2026 ║
|
||||
║ ║
|
||||
║ Starten auf: http://localhost:5000 ║
|
||||
║ ⚠️ ÄNDERE DIE PASSWÖRTER VOR PRODUKTIVBEREITSTELLUNG! ║
|
||||
╚═══════════════════════════════════════════════════════════╝
|
||||
""")
|
||||
|
||||
app.run(
|
||||
host="0.0.0.0",
|
||||
port=5000,
|
||||
debug=False, # In Produktion: False
|
||||
use_reloader=True
|
||||
)
|
||||
@@ -0,0 +1,68 @@
|
||||
"""
|
||||
Naue Roll Calculator – Production Configuration Template
|
||||
|
||||
Nutze diese Datei als Vorlage für Produktionsumgebungen.
|
||||
Speichere sensible Daten in Umgebungsvariablen oder verschlüsselten Config-Files!
|
||||
"""
|
||||
|
||||
import os
|
||||
from datetime import timedelta
|
||||
|
||||
# ============================================================================
|
||||
# ENVIRONMENT
|
||||
# ============================================================================
|
||||
|
||||
ENV = os.getenv("FLASK_ENV", "production")
|
||||
DEBUG = os.getenv("DEBUG", "False").lower() == "true"
|
||||
|
||||
# ============================================================================
|
||||
# AUTHENTICATION
|
||||
# ============================================================================
|
||||
|
||||
# Benutzer aus Umgebungsvariablen laden (Docker/K8s)
|
||||
BETA_USERS = {
|
||||
os.getenv("BETA_USER_1", "beta"): os.getenv("BETA_PASS_1", "changeme"),
|
||||
}
|
||||
|
||||
ADMIN_USERS = {
|
||||
os.getenv("ADMIN_USER", "admin"): os.getenv("ADMIN_PASS", "changeme"),
|
||||
}
|
||||
|
||||
# ============================================================================
|
||||
# SECURITY
|
||||
# ============================================================================
|
||||
|
||||
SECRET_KEY = os.getenv("SECRET_KEY", "CHANGE_ME_IN_PRODUCTION")
|
||||
SESSION_COOKIE_SECURE = True # HTTPS only
|
||||
SESSION_COOKIE_HTTPONLY = True
|
||||
SESSION_COOKIE_SAMESITE = "Lax"
|
||||
PERMANENT_SESSION_LIFETIME = timedelta(hours=8)
|
||||
|
||||
# ============================================================================
|
||||
# LOGGING
|
||||
# ============================================================================
|
||||
|
||||
LOG_FILE = os.getenv("LOG_FILE", "access_log.json")
|
||||
LOG_ROTATION = os.getenv("LOG_ROTATION", "daily") # daily, weekly, monthly
|
||||
|
||||
# ============================================================================
|
||||
# RATE LIMITING (optional)
|
||||
# ============================================================================
|
||||
|
||||
RATELIMIT_ENABLED = os.getenv("RATELIMIT_ENABLED", "True").lower() == "true"
|
||||
RATELIMIT_DEFAULT = "100 per hour" # Max 100 requests pro Stunde
|
||||
|
||||
# ============================================================================
|
||||
# MONITORING
|
||||
# ============================================================================
|
||||
|
||||
SENTRY_DSN = os.getenv("SENTRY_DSN", None) # Optional: Error Tracking
|
||||
DATADOG_ENABLED = os.getenv("DATADOG_ENABLED", "False").lower() == "true"
|
||||
|
||||
# ============================================================================
|
||||
# DATABASE (falls später benötigt)
|
||||
# ============================================================================
|
||||
|
||||
DB_URL = os.getenv("DATABASE_URL", None)
|
||||
|
||||
print(f"[Config] Environment: {ENV}, Debug: {DEBUG}")
|
||||
@@ -0,0 +1,40 @@
|
||||
# Python
|
||||
__pycache__/
|
||||
*.pyc
|
||||
*.pyo
|
||||
*.pyd
|
||||
.Python
|
||||
env/
|
||||
venv/
|
||||
.venv
|
||||
*.egg-info/
|
||||
dist/
|
||||
build/
|
||||
|
||||
# Logging
|
||||
access_log.json
|
||||
*.log
|
||||
|
||||
# IDE
|
||||
.vscode/
|
||||
.idea/
|
||||
*.swp
|
||||
*.swo
|
||||
*~
|
||||
|
||||
# OS
|
||||
.DS_Store
|
||||
Thumbs.db
|
||||
|
||||
# Flask
|
||||
instance/
|
||||
.webassets-cache
|
||||
|
||||
# Testing
|
||||
.pytest_cache/
|
||||
.coverage
|
||||
|
||||
# Environment
|
||||
.env
|
||||
.env.local
|
||||
.env.*.local
|
||||
@@ -0,0 +1,7 @@
|
||||
Flask==2.3.3
|
||||
Flask-HTTPAuth==4.8.0
|
||||
Werkzeug==2.3.7
|
||||
click==8.1.7
|
||||
itsdangerous==2.1.2
|
||||
Jinja2==3.1.2
|
||||
MarkupSafe==2.1.3
|
||||
Reference in New Issue
Block a user